2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62104 | CRITICAL | 10 | 0.6% | Sep 17, 2026 | Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions. |
| CVE-2026-62101 | CRITICAL | 9.8 | — | Sep 17, 2026 | Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions. |
| CVE-2026-92860 | CRITICAL | 9.1 | 0.5% | Sep 17, 2026 | A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fm... |
| CVE-2026-90823 | CRITICAL | 9.8 | — | Sep 17, 2026 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based b... |
| CVE-2026-90822 | CRITICAL | 9.8 | — | Sep 17, 2026 | FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command i... |
| CVE-2026-15688 | CRITICAL | 9.2 | — | Sep 17, 2026 | Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control S... |
| CVE-2026-88795 | CRITICAL | 9 | — | Sep 17, 2026 | The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, ... |
| CVE-2026-86710 | CRITICAL | 9.8 | — | Sep 17, 2026 | The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, m... |
| CVE-2026-86709 | CRITICAL | 9.8 | — | Sep 17, 2026 | The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication ... |
| CVE-2026-86707 | CRITICAL | 9.8 | — | Sep 17, 2026 | The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is on... |
| CVE-2026-87796 | CRITICAL | 9.8 | 0.6% | Sep 17, 2026 | The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, ... |
| CVE-2026-61594 | CRITICAL | 9.1 | — | Sep 16, 2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ... |
| CVE-2026-92805 | CRITICAL | 9.8 | 0.3% | Sep 16, 2026 | UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in Conf... |
| CVE-2026-92787 | CRITICAL | 9.8 | 0.7% | Sep 16, 2026 | Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypas... |
| CVE-2026-76460 | CRITICAL | 10 | 14.0% | Sep 16, 2026 | A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to byp... |
| CVE-2026-75513 | CRITICAL | 9.1 | 0.4% | Sep 16, 2026 | Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marte... |
| CVE-2026-20332 | CRITICAL | 9.9 | — | Sep 16, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl... |
| CVE-2026-20284 | CRITICAL | 9.1 | — | Sep 16, 2026 | A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection ... |
| CVE-2026-92808 | CRITICAL | 10 | — | Sep 16, 2026 | A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An un... |
| CVE-2026-89083 | CRITICAL | 9.3 | — | Sep 16, 2026 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, ... |
| CVE-2026-89082 | CRITICAL | 9.3 | — | Sep 16, 2026 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, ... |
| CVE-2026-88592 | CRITICAL | 9.1 | 0.2% | Sep 16, 2026 | kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFi... |
| CVE-2026-76423 | CRITICAL | 10 | — | Sep 16, 2026 | A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain a... |
| CVE-2026-20341 | CRITICAL | 9.1 | — | Sep 16, 2026 | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenti... |
| CVE-2026-20330 | CRITICAL | 9.9 | — | Sep 16, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now